Suricata IDS — network detector

Installed, but the service is not running. Start it and enable autostart:
sudo systemctl enable --now suricata
How to set up (FAQ)
Suricata
Not running
IDS / IPS
Alerts in 24h
305
Alerts in 24h
Top categories
5
Category
Top sources
8
IP address
Top categories
Attempted Information Leak 98
Web Application Attack 73
Misc Attack 55
Detection of a Network Scan 46
Potentially Bad Traffic 34
Top sources
198.51.100.13 23
198.51.100.12 22
198.51.100.11 18
198.51.100.15 16
198.51.100.14 14
198.51.100.16 14
198.51.100.18 12
198.51.100.17 5
Recent alerts
Time Signature Source Destination
2026-10-11 19:27 ET POLICY curl User-Agent 198.51.100.24 203.0.113.10
2026-10-11 19:15 ET SCAN Nmap Scripting Engine 198.51.100.12 203.0.113.10
2026-10-11 18:37 GPL WEB_SERVER /etc/passwd access 198.51.100.21 203.0.113.10
2026-10-11 19:07 GPL WEB_SERVER /etc/passwd access 198.51.100.12 203.0.113.10
2026-10-11 18:38 GPL WEB_SERVER /etc/passwd access 198.51.100.14 203.0.113.10
2026-10-11 16:52 ET WEB_SERVER SQL Injection Attempt 198.51.100.24 203.0.113.10
2026-10-11 17:42 ET WEB_SERVER WordPress login bruteforce 198.51.100.14 203.0.113.10
2026-10-11 15:24 ET SCAN Potential SSH Scan 198.51.100.26 203.0.113.10
2026-10-11 15:01 ET SCAN Nmap Scripting Engine 198.51.100.22 203.0.113.10
2026-10-11 16:44 ET POLICY curl User-Agent 198.51.100.16 203.0.113.10
2026-10-11 14:58 ET SCAN Nmap Scripting Engine 198.51.100.12 203.0.113.10
2026-10-11 18:12 ET WEB_SERVER WordPress login bruteforce 198.51.100.14 203.0.113.10
2026-10-11 17:57 ET SCAN Potential SSH Scan 198.51.100.34 203.0.113.10
2026-10-11 14:34 ET POLICY curl User-Agent 198.51.100.19 203.0.113.10
2026-10-11 11:01 ET SCAN Nmap Scripting Engine 198.51.100.21 203.0.113.10
2026-10-11 11:27 GPL WEB_SERVER /etc/passwd access 198.51.100.24 203.0.113.10
2026-10-11 18:04 GPL WEB_SERVER /etc/passwd access 198.51.100.33 203.0.113.10
2026-10-11 11:52 ET SCAN Nmap Scripting Engine 198.51.100.18 203.0.113.10
2026-10-11 10:56 ET SCAN Nmap Scripting Engine 198.51.100.18 203.0.113.10
2026-10-11 07:55 ET SCAN Nmap Scripting Engine 198.51.100.18 203.0.113.10
2026-10-11 11:25 ET WEB_SERVER WordPress login bruteforce 198.51.100.19 203.0.113.10
2026-10-11 16:12 ET WEB_SERVER SQL Injection Attempt 198.51.100.23 203.0.113.10
2026-10-11 14:15 ET POLICY curl User-Agent 198.51.100.21 203.0.113.10
2026-10-11 13:53 ET POLICY curl User-Agent 198.51.100.23 203.0.113.10
2026-10-11 06:46 ET WEB_SERVER SQL Injection Attempt 198.51.100.14 203.0.113.10
2026-10-11 03:07 ET POLICY curl User-Agent 198.51.100.32 203.0.113.10
2026-10-11 10:27 GPL WEB_SERVER /etc/passwd access 198.51.100.13 203.0.113.10
2026-10-11 05:14 ET WEB_SERVER SQL Injection Attempt 198.51.100.28 203.0.113.10
2026-10-11 15:31 ET SCAN Potential SSH Scan 198.51.100.28 203.0.113.10
2026-10-11 07:44 GPL WEB_SERVER /etc/passwd access 198.51.100.28 203.0.113.10

Suricata alerts without an ELK stack

Suricata writes its findings to eve.json, one JSON object per event, and the usual advice is to ship that into Elasticsearch and look at it through Kibana. On a cluster that is sound. On a single VPS it means running a search engine, a log shipper and a dashboard server — several gigabytes of memory and a second system to maintain — so that you can read alerts from the machine they were already written on.

This page reads eve.json directly, along with fast.log where that is what your build produces. It shows the alerts from the last twenty-four hours grouped by category, the addresses generating the most of them, and the individual signatures with source, destination, protocol and severity.

If Suricata is running but reporting nothing, the cause is almost always rules rather than traffic: a fresh install ships with no signatures until suricata-update has run at least once. The other common surprise is severity. Most of what a public-facing sensor reports is low-severity scanning that never becomes anything, so read the categories before the count.

A sensor on the wire has a limit people trip over regularly: encrypted traffic looks to it like a stream of bytes. It will tell you a connection to your site came from this address; it will not tell you the request carried an attempted SQL injection. That is read inside the web server, after decryption, by ModSecurity. The two do not replace each other: one looks at the network from outside, the other at the request from inside.